First published: Wed Dec 11 2019(Updated: )
A flaw was found in the Linux kernel’s implementation of the WiFi station handoff code. An attacker within the radio range could use this flaw to deny a valid device from joining the access point.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1127.19.1.rt56.1116.el7 | 0:3.10.0-1127.19.1.rt56.1116.el7 |
redhat/kernel | <0:3.10.0-1127.el7 | 0:3.10.0-1127.el7 |
redhat/kernel-alt | <0:4.14.0-115.19.1.el7a | 0:4.14.0-115.19.1.el7a |
redhat/kernel-rt | <0:4.18.0-193.rt13.51.el8 | 0:4.18.0-193.rt13.51.el8 |
redhat/kernel | <0:4.18.0-193.el8 | 0:4.18.0-193.el8 |
Linux Kernel | <5.3 | |
Debian | =8.0 | |
Debian | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Cloud Backup | ||
NetApp Data Availability Services | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp AFF A700s Firmware | ||
NetApp A700s | ||
NetApp H610S Firmware | ||
NetApp H610S Firmware | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 | ||
Oracle SD-WAN Edge | =8.2 | |
All of | ||
NetApp AFF A700s Firmware | ||
NetApp A700s | ||
All of | ||
NetApp H610S Firmware | ||
NetApp H610S Firmware | ||
All of | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
All of | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
All of | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
At this time there is no known mitigations to this issue other than to install the updated kernel package.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-5108 is categorized as a denial-of-service (DoS) vulnerability in the Linux kernel.
To mitigate CVE-2019-5108, upgrade to a patched version of the Linux kernel available after version 5.3.
CVE-2019-5108 affects Linux kernels prior to version 5.3, including versions of kernel-rt and kernel-alt on Red Hat.
CVE-2019-5108 requires an attacker to be within radio range to exploit the vulnerability.
CVE-2019-5108 impacts various versions of the Linux kernel across different distributions, including Red Hat, Debian, and Ubuntu.